Skip to main content
security

Recovery Codes

Learn how to generate and use recovery codes for account access when you lose your 2FA device or passkey.

Recovery codes are one-time-use backup codes that let you sign in to your Ottili ONE account when you lose access to your two-factor authentication device or passkey.

What Are Recovery Codes?

Recovery codes are 8-character alphanumeric codes that serve as a backup authentication method. Each code can be used exactly once to bypass your normal 2FA requirement and sign in to your account.

Key characteristics:*

  • One-time use*: Each code works only once
  • Backup method*: Use when you can't access your 2FA device or passkey
  • Generated in sets*: You get 8 codes at a time
  • Replaceable*: Generate new codes anytime (old codes are invalidated)

Why You Need Recovery Codes

Recovery codes are your last line of defense when:

  • Lost phone*: Your phone with authenticator app is lost, stolen, or broken
  • Deleted app*: You accidentally deleted your authenticator app
  • New device*: You got a new phone and didn't transfer your authenticator
  • Passkey issues*: Your passkey isn't working or you lost your security key
  • Travel*: You're traveling without your usual 2FA device

Without recovery codes, you could be permanently locked out of your account.*

Generating Recovery Codes

Step 1: Navigate to Recovery Codes

1. Sign in to your Ottili ONE account

2. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

3. Scroll to "Recovery codes" section

Step 2: Generate Codes

1. Click "Generate new codes"

2. Enter your password to confirm

3. Your 8 recovery codes are displayed

Step 3: Save Your Codes

Critical*: Save your codes in a secure location immediately. You won't see them again.

Recommended storage methods:*

  • Password manager*: Store in 1Password, Bitwarden, etc.
  • Encrypted file*: Save in an encrypted document
  • Printed copy*: Print and store in a safe/lockbox
  • Multiple locations*: Store in 2+ secure locations for redundancy

Never:*

  • ❌ Store codes in plain text on your computer
  • ❌ Email codes to yourself
  • ❌ Take a screenshot and leave in photos
  • ❌ Share codes with anyone
  • ❌ Store codes in your browser notes

Using Recovery Codes

When to Use Recovery Codes

Use a recovery code when:

  • You can't access your authenticator app
  • Your passkey isn't working
  • You lost your 2FA device
  • You're on a new device without 2FA set up

Step 1: Start Sign-In

1. Go to [auth.ottili.one/login](https://auth.ottili.one/login)

2. Enter your email and password

3. When prompted for 2FA code, click "Use a recovery code"

Step 2: Enter Recovery Code

1. Enter one of your 8-character recovery codes

2. Click "Verify"

3. You're signed in!

Step 3: Regain Account Access

After signing in with a recovery code:

1. Set up 2FA again* if you lost your device

2. Generate new recovery codes* (the used code is now invalid)

3. Save the new codes* securely

Managing Recovery Codes

View Recovery Code Status

Check how many recovery codes you have remaining:

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Look at "Recovery codes" section

3. You'll see: "X of 8 codes remaining"

Generate New Codes

Generate new codes when:

  • You've used some codes and want a full set of 8
  • You lost your saved codes
  • You suspect your codes were compromised
  • It's been over a year since you generated them

To generate new codes:*

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Click "Generate new codes"

3. Enter your password

4. Save the new codes securely

Important*: Generating new codes invalidates all previous codes.

Test Your Codes

Periodically verify your codes work:

1. Sign out of your account

2. Sign in with email + password

3. Use a recovery code instead of 2FA

4. Verify you can sign in

5. Generate new codes (since you used one)

Recovery Code Security

How Recovery Codes Work

  • Generated securely*: Codes are cryptographically random
  • Stored hashed*: Ottili ONE stores only hashed versions (like passwords)
  • One-time use*: Each code is invalidated after use
  • No reuse*: Used codes cannot be used again

Security Best Practices

1. Treat like passwords*: Recovery codes are as sensitive as your password

2. Store securely*: Use a password manager or encrypted storage

3. Don't share*: Never share codes with anyone, including Ottili support

4. Rotate regularly*: Generate new codes every 6-12 months

5. Multiple backups*: Store in 2+ secure locations

What If Someone Gets My Codes?

If you suspect your recovery codes were compromised:

1. Generate new codes immediately* at [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Change your password* at [auth.ottili.one/change-password](https://auth.ottili.one/change-password)

3. Review active sessions* at [auth.ottili.one/sessions](https://auth.ottili.one/sessions)

4. Sign out suspicious sessions*

Troubleshooting

"Invalid recovery code" Error

Cause*: The code was already used, typed incorrectly, or is from an old set.

Solution*:

1. Double-check you typed the code correctly (no spaces, correct characters)

2. Try a different recovery code from your current set

3. If all codes fail, contact support at support@ottili.one

"No recovery codes available" Message

Cause*: You haven't generated recovery codes yet, or all codes have been used.

Solution*:

1. Sign in with your normal 2FA method

2. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

3. Generate new recovery codes

Lost All Recovery Codes and 2FA Device

Cause*: You lost both your 2FA device and recovery codes.

Solution*:

1. Try signing in with a passkey if you have one set up

2. Contact support at support@ottili.one

3. Provide proof of identity (government ID, account details)

4. Support will verify your identity and help you regain access

5. Note*: Account recovery may take 3-5 business days for security

Recovery Code Not Accepted After Password Change

Cause*: Password changes don't invalidate recovery codes, but you may be using an old set.

Solution*:

1. Use codes from your most recent generation

2. If unsure, generate new codes after signing in

Best Practices

1. Generate Codes Immediately After Enabling 2FA

Don't wait until you lose your device. Generate recovery codes as soon as you enable 2FA or passkeys.

2. Store in Multiple Secure Locations

Redundancy prevents lockout:

  • Password manager (primary)
  • Encrypted USB drive (backup)
  • Printed copy in safe (emergency)

3. Test Your Codes Periodically

Every 3-6 months:

1. Sign out

2. Sign in with a recovery code

3. Verify it works

4. Generate new codes

4. Update Codes After Major Changes

Generate new codes after:

  • Changing your password
  • Losing a device with saved codes
  • Suspecting a security breach
  • Annually (as part of security review)

5. Never Store Codes with Your Password

If someone gets both your password and recovery codes, they have full access. Store them separately.

Recovery Scenarios

Scenario 1: Lost Phone with Authenticator App

Situation*: Your phone was lost/stolen and you can't access your authenticator app.

Recovery steps*:

1. Get a new phone

2. Go to [auth.ottili.one/login](https://auth.ottili.one/login)

3. Enter email + password

4. Click "Use a recovery code"

5. Enter one of your recovery codes

6. Sign in successfully

7. Set up authenticator app on new phone

8. Generate new recovery codes

Scenario 2: Deleted Authenticator App

Situation*: You accidentally deleted your authenticator app and lost all your 2FA codes.

Recovery steps*:

1. Reinstall authenticator app

2. Go to [auth.ottili.one/login](https://auth.ottili.one/login)

3. Enter email + password

4. Use a recovery code to sign in

5. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

6. Disable 2FA

7. Re-enable 2FA and scan new QR code

8. Generate new recovery codes

Scenario 3: New Phone, Didn't Transfer Authenticator

Situation*: You got a new phone and didn't transfer your authenticator app data.

Recovery steps*:

1. Try to recover authenticator data from old phone (if available)

2. If not possible, use a recovery code to sign in

3. Disable and re-enable 2FA to get new QR code

4. Scan QR code with new phone

5. Generate new recovery codes

Scenario 4: Passkey Not Working

Situation*: Your passkey isn't working (browser issue, security key lost, etc.).

Recovery steps*:

1. Try a different browser or device

2. If still not working, use a recovery code to sign in

3. Go to [auth.ottili.one/passkeys](https://auth.ottili.one/passkeys)

4. Delete the non-working passkey

5. Register a new passkey

6. Generate new recovery codes

Frequently Asked Questions

How many recovery codes do I get?

You get 8 recovery codes per generation. Each code can be used once.

Do recovery codes expire?

No, recovery codes don't expire. They remain valid until used or until you generate new codes (which invalidates old ones).

Can I reuse a recovery code?

No, each recovery code can only be used once. After use, it's permanently invalidated.

What happens if I use all 8 codes?

Generate new codes at [auth.ottili.one/mfa](https://auth.ottili.one/mfa). You'll get a fresh set of 8 codes.

Can I see my recovery codes again after generating them?

No, for security reasons, codes are only shown once when generated. If you lose them, generate new codes.

Do recovery codes work if I change my password?

Yes, recovery codes continue to work after password changes. However, we recommend generating new codes after a password change for security.

Can someone use my recovery code if they find it?

Yes! Recovery codes are like passwords. Anyone with a valid code can bypass your 2FA. Store them securely.

Should I share recovery codes with my team?

No, recovery codes are personal to your account. Each team member should have their own account with their own recovery codes.

What's the difference between recovery codes and backup codes?

They're the same thing. Different services use different names (recovery codes, backup codes, emergency codes).

Related Articles

  • [Two-Factor Authentication](/docs/auth-two-factor-authentication) - Set up 2FA with authenticator app or SMS
  • [Passkeys](/docs/auth-passkeys) - Secure, passwordless authentication
  • [Active Sessions](/docs/auth-sessions) - Manage your login sessions

Need Help?

If you're having trouble with recovery codes:

  • Check our [troubleshooting guide](#troubleshooting) above
  • Visit our [Help Center](https://help.ottili.one)
  • Contact support at support@ottili.one

Emergency account recovery*: If you've lost both your 2FA device and recovery codes, contact support at support@ottili.one with proof of identity.

Was this article helpful?